CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2013-4830

    Last Modified: 11 Apr 2025

    HP Service Manager 9.30 through 9.32 allows remote attackers to execute arbitrary code via an unspecified "injection" approach.

    Published: 16 Oct 2013
    5.5
    Medium

    CVE-2013-4831

    Last Modified: 11 Apr 2025

    HP Service Manager 9.30 through 9.32 does not properly manage privileges, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

    Published: 16 Oct 2013
    4
    Medium

    CVE-2013-4832

    Last Modified: 11 Apr 2025

    HP Service Manager 9.30 through 9.32 allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 16 Oct 2013
    7.2
    High

    CVE-2013-5030

    Last Modified: 11 Apr 2025

    Ruckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and subsequently access certain configuration/ and maintenance/ scripts, by constructing a crafted URI after receiving an authentication error for an arbitrary login attempt.

    Published: 16 Oct 2013
    3.5
    Low

    CVE-2013-5390

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Oct 2013
    6.4
    Medium

    CVE-2013-5535

    Last Modified: 11 Apr 2025

    The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419.

    Published: 16 Oct 2013
    5
    Medium

    CVE-2013-5538

    Last Modified: 11 Apr 2025

    The Sponsor Portal in Cisco Identity Services Engine (ISE) uses weak permissions for uploaded files, which allows remote attackers to read arbitrary files via a direct request, aka Bug ID CSCui67506.

    Published: 16 Oct 2013
    6
    Medium

    CVE-2013-5539

    Last Modified: 11 Apr 2025

    The upload-dialog implementation in Cisco Identity Services Engine (ISE) allows remote authenticated users to upload files with an arbitrary file type, and consequently conduct attacks against unspecified other systems, via a crafted file, aka Bug ID CSCui67511.

    Published: 16 Oct 2013
    6.8
    Medium

    CVE-2013-5540

    Last Modified: 11 Apr 2025

    The file-upload feature in Cisco Identity Services Engine (ISE) allows remote authenticated users to cause a denial of service (disk consumption and administration-interface outage) by uploading many files, aka Bug ID CSCui67519.

    Published: 16 Oct 2013
    3.5
    Low

    CVE-2013-5541

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the file-upload interface in Cisco Identity Services Engine (ISE) allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename, aka Bug ID CSCui67495.

    Published: 16 Oct 2013
    4.1
    Medium

    CVE-2013-5208

    Last Modified: 11 Apr 2025

    HR Systems Strategies info:HR HRIS 7.9 does not properly protect the database password, which allows local users to bypass intended database restrictions by accessing the USERPW registry key and bypassing an unspecified obfuscation technique.

    Published: 16 Oct 2013
    7.5
    High

    CVE-2013-5393

    Last Modified: 11 Apr 2025

    The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors.

    Published: 16 Oct 2013
    6
    Medium

    CVE-2013-4299

    Last Modified: 11 Apr 2025

    Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device.

    Published: 16 Oct 2013
    4.3
    Medium

    CVE-2013-4389

    Last Modified: 11 Apr 2025

    Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.

    Published: 16 Oct 2013
    3.3
    Low

    CVE-2013-2102

    Last Modified: 11 Apr 2025

    The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.

    Published: 16 Oct 2013
    2.1
    Low

    CVE-2014-1445

    Last Modified: 11 Apr 2025

    The wanxl_ioctl function in drivers/net/wan/wanxl.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an ioctl call.

    Published: 16 Oct 2013
    4.3
    Medium

    CVE-2013-5913

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the getRecommSearch function in recommlist.php in OXID eShop before 4.6.7, Professional and Community Edition 4.7.x before 4.7.8, and Enterprise Edition 5.x before 5.0.8 allows remote attackers to inject arbitrary web script or HTML via the searchrecomm parameter.

    Published: 15 Oct 2013
    6.4
    Medium

    CVE-2013-3829

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java SE, Java SE Embedded component in Oracle Java SE Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.

    Published: 15 Oct 2013
    4
    Medium

    CVE-2013-3839

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

    Published: 15 Oct 2013
    2.6
    Low

    CVE-2013-5772

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u40 and earlier and Java SE 6u60 and earlier allows remote attackers to affect integrity via unknown vectors related to jhat.

    Published: 15 Oct 2013
    7.5
    High

    CVE-2013-5775

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java SE and JavaFX components in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-5777.

    Published: 15 Oct 2013
    5
    Medium

    CVE-2013-5776

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment.

    Published: 15 Oct 2013
    4
    Medium

    CVE-2013-5786

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-5793.

    Published: 15 Oct 2013
    3.5
    Low

    CVE-2013-5793

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-5786.

    Published: 15 Oct 2013
    3.5
    Low

    CVE-2013-5797

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and JavaFX 2.2.40 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.

    Published: 15 Oct 2013
    7.5
    High

    CVE-2013-5802

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXP.

    Published: 15 Oct 2013
    10
    Critical

    CVE-2013-5809

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-5829.

    Published: 15 Oct 2013
    10
    Critical

    CVE-2013-5814

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.

    Published: 15 Oct 2013
    5
    Medium

    CVE-2013-5823

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via unknown vectors related to Security.

    Published: 15 Oct 2013
    10
    Critical

    CVE-2013-5829

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-5809.

    Published: 15 Oct 2013
    5
    Medium

    CVE-2013-5831

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5818 and CVE-2013-5819.

    Published: 15 Oct 2013
    9.3
    Critical

    CVE-2013-5846

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, and JavaFX 2.2.40 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.

    Published: 15 Oct 2013
    5
    Medium

    CVE-2013-5848

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and JavaFX 2.2.40 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment.

    Published: 15 Oct 2013
    4
    Medium

    CVE-2013-5767

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

    Published: 15 Oct 2013
    2.1
    Low

    CVE-2013-5770

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Locking.

    Published: 15 Oct 2013
    5
    Medium

    CVE-2013-5778

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, 6u60 and earlier, 5.0u51 and earlier, and Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to 2D.

    Published: 15 Oct 2013
    4.3
    Medium

    CVE-2013-5780

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.

    Published: 15 Oct 2013
    4.3
    Medium

    CVE-2013-5784

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via vectors related to SCRIPTING.

    Published: 15 Oct 2013
    10
    Critical

    CVE-2013-5788

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

    Published: 15 Oct 2013
    10
    Critical

    CVE-2013-5789

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5824, CVE-2013-5832, and CVE-2013-5852.

    Published: 15 Oct 2013
    4.3
    Medium

    CVE-2013-5790

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to BEANS.

    Published: 15 Oct 2013
    4.3
    Medium

    CVE-2013-5800

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JGSS.

    Published: 15 Oct 2013
    6.4
    Medium

    CVE-2013-5804

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, and JRockit R27.7.6 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Javadoc.

    Published: 15 Oct 2013
    9.3
    Critical

    CVE-2013-5806

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Swing, a different vulnerability than CVE-2013-5805.

    Published: 15 Oct 2013
    9.3
    Critical

    CVE-2013-5810

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Oct 2013
    5
    Medium

    CVE-2013-5818

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5819 and CVE-2013-5831.

    Published: 15 Oct 2013
    5
    Medium

    CVE-2013-5820

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via vectors related to JAX-WS.

    Published: 15 Oct 2013
    9.3
    Critical

    CVE-2013-5832

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5789, CVE-2013-5824, and CVE-2013-5852.

    Published: 15 Oct 2013
    9.3
    Critical

    CVE-2013-5838

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u25 and earlier, and Java SE Embedded 7u25 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

    Published: 15 Oct 2013
    9.3
    Critical

    CVE-2013-5844

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.

    Published: 15 Oct 2013